Actor Profile

ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms. The group specializes in targeting organizations through supply-chain compromises and credential-based attacks, focusing on exfiltrating sensitive data rather than deploying ransomware. ShinyHunters has been active since at least 2020 and has claimed responsibility for numerous high-profile breaches across multiple sectors. The group's primary motivation is financial extortion, threatening to publicly release stolen data if victims do not pay or negotiate by specified deadlines.

TTPs (Tactics, Techniques, Procedures)

ShinyHunters employed supply-chain attack techniques to obtain initial access credentials, consistent with T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). The threat actors leveraged stolen credentials to gain Valid Accounts (T1078) for accessing multiple Ernst & Young environments including Jira, GitHub, and Azure platforms. The attack involved accessing a third-party IT service management platform between March 28 and April 12, 2026, demonstrating persistence and data collection capabilities. The group exfiltrated support tickets and documents containing client tax information (T1005: Data from Local System, T1567: Exfiltration Over Web Service). ShinyHunters operates a data leak site for extortion purposes (T1657: Financial Theft), threatening public disclosure of stolen data to coerce payment.

Targets & Patterns

ShinyHunters targets organizations across diverse sectors with valuable data holdings. In this campaign, the group targeted Ernst & Young, a major professional services firm, specifically compromising systems containing client tax information, personal data, and financial records. The attack focused on a third-party IT service management platform used by EY's IT personnel for tax-related client support, demonstrating the group's preference for supply-chain vectors that provide access to high-value targets. Previous ShinyHunters campaigns have targeted organizations including NAIC (via PeopleSoft), Abbott, Medtronic, and Kodak, indicating a pattern of attacking large enterprises and healthcare organizations with substantial customer databases. The group selects targets based on the sensitivity and monetization potential of accessible data rather than specific industry focus.

Historical Context

ShinyHunters has maintained consistent operations since at least 2020, establishing a reputation for large-scale data breaches and extortion. Recent campaigns attributed to the group include the NAIC breach exploiting PeopleSoft systems, attacks on healthcare organizations Medtronic and Abbott, and the Kodak data breach. The Ernst & Young incident follows the group's established operational pattern: conducting supply-chain compromises to obtain credentials, accessing multiple internal systems (cloud platforms, development environments, and collaboration tools), exfiltrating sensitive data over extended periods, and leveraging their data leak site for extortion with specific deadlines. The group's claimed access to Jira, GitHub, and Azure environments in the EY breach mirrors their multi-platform targeting approach observed in previous incidents. ShinyHunters-linked data has also been exploited in secondary criminal activities, including sextortion campaigns using stolen information.

Defensive Recommendations

  • Implement robust third-party risk management programs with continuous monitoring of supply-chain vendors, particularly those with privileged access to internal systems or sensitive data
  • Deploy credential-based attack detection by monitoring for anomalous authentication patterns across cloud platforms (Azure, GitHub) and collaboration tools (Jira), including impossible travel scenarios and unusual access times (T1078)
  • Establish data exfiltration detection capabilities using network monitoring and DLP solutions to identify large-scale document downloads or transfers to external destinations over extended periods (T1567)
  • Enforce multi-factor authentication (MFA) across all third-party integrations and privileged access pathways, with phishing-resistant MFA methods for high-value systems
  • Conduct regular audits of third-party platform access logs and implement automated alerting for unusual activity patterns, particularly in IT service management and ticketing systems containing client data